analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Doc

Full analysis: https://app.any.run/tasks/b1583bd5-5173-4653-acd7-f8ad6668c7e9
Verdict: Malicious activity
Analysis date: December 06, 2018, 07:41:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

C2CB276B3DAD889F878DEBE7650119E4

SHA1:

44476C1AF55AC73F269B00C9A1F9BEFF1F450255

SHA256:

3C99E7A4B4C262836E2E778B40A2FD4CC7F097EEC752C69D5FCEA357ED83751E

SSDEEP:

6144:IgACqOdm5y+DWfVSCwvu/SZb6zx+SOmVY1mMbSvS/BVlH3/W3cT8Tui3YRbfOAew:TDm5DiuvBZGLVgt8Qh3e5lHzs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • RegAsm.exe (PID: 2572)
      • Doc.exe (PID: 2980)
    • Application was dropped or rewritten from another process

      • RegAsm.exe (PID: 2572)
      • services.exe (PID: 3968)
  • SUSPICIOUS

    • Creates files in the user directory

      • RegAsm.exe (PID: 2572)
    • Executable content was dropped or overwritten

      • RegAsm.exe (PID: 2572)
      • Doc.exe (PID: 2980)
    • Creates executable files which already exist in Windows

      • RegAsm.exe (PID: 2572)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (81)
.dll | Win32 Dynamic Link Library (generic) (7.2)
.exe | Win32 Executable (generic) (4.9)
.exe | Win16/32 Executable Delphi generic (2.2)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

ProductName: 51d2d5c6-a33d-4000-8614-294cfebb6ca8
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
OriginalFileName: 77f3bf1e-2783-4030-ace5-a6ed6d6398d1.exe
LegalCopyright: 193fa18b-c8c3-4227-b271-e32a3a9a8a6e
FileDescription: 43f46455-2c6d-4171-861d-b642224b4e0
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Unknown (0)
FileFlags: (none)
FileFlagsMask: 0x0000
ProductVersionNumber: 0.0.0.0
FileVersionNumber: 0.0.0.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x720ee
UninitializedDataSize: -
InitializedDataSize: 70656
CodeSize: 459264
LinkerVersion: 6
PEType: PE32
TimeStamp: 2018:12:04 12:23:17+01:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start doc.exe regasm.exe services.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2980"C:\Users\admin\AppData\Local\Temp\Doc.exe" C:\Users\admin\AppData\Local\Temp\Doc.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
43f46455-2c6d-4171-861d-b642224b4e0
Exit code:
0
Version:
1.0.0.0
2572"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
Doc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.6.1055.0 built by: NETFXREL2
3968"C:\Users\admin\AppData\Roaming\services.exe"C:\Users\admin\AppData\Roaming\services.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.6.1055.0 built by: NETFXREL2
Total events
8
Read events
3
Write events
5
Delete events
0

Modification events

(PID) Process:(2980) Doc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:startupname
Value:
C:\Users\admin\filename.exe
(PID) Process:(2572) RegAsm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:MaxConnectionsPer1_0Server
Value:
10
(PID) Process:(2572) RegAsm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:MaxConnectionsPerServer
Value:
10
(PID) Process:(2572) RegAsm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\0SAI4AY4J1
Operation:writeName:inst
Value:
E3412070D9C894403A08132FB681E156008F90A806FCCC1EE243CAE90995EED84D924E1A30C2E3ECBD612723B7E02C8E1791638AE67755782D2E641CF7D48DBEF8E9959BD70E53429107B40C6E6EF5D54A27D6A41B346F38
(PID) Process:(2572) RegAsm.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Google App Update
Value:
C:\Users\admin\AppData\Roaming\services.exe
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2980Doc.exeC:\Users\admin\filename.exeexecutable
MD5:C2CB276B3DAD889F878DEBE7650119E4
SHA256:3C99E7A4B4C262836E2E778B40A2FD4CC7F097EEC752C69D5FCEA357ED83751E
2572RegAsm.exeC:\Users\admin\AppData\Roaming\services.exeexecutable
MD5:911BDF77EB94E48CA524252A3FD47019
SHA256:A07564A8771DAFA3EBE9ACEAA20C327EFA2D0AC2EDC06B2BBC3EEBDC66600641
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info